Path: csiph.com!x330-a1.tempe.blueboxinc.net!usenet.pasdenom.info!news.albasani.net!eternal-september.org!feeder.eternal-september.org!.POSTED!not-for-mail From: Arno Welzel Newsgroups: comp.lang.php Subject: Re: session handler auto log out Date: Wed, 23 Nov 2011 20:42:40 +0100 Organization: A noiseless patient Spider Lines: 36 Message-ID: <4ECD4CB0.5020903@arnowelzel.de> References: <11984037.1120.1321742991368.JavaMail.geo-discussion-forums@prlm15> <4ECA5B14.5020200@arnowelzel.de> <4ECA60DE.6070301@arnowelzel.de> <4ECB82D1.2000902@arnowelzel.de> <4ECBC5FC.4050306@arnowelzel.de> <4ECCBA39.9070501@arnowelzel.de> <4ecd4241$0$28492$a8266bb1@newsreader.readnews.com> Mime-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Injection-Info: mx04.eternal-september.org; posting-host="dmYg0DIsuEi3Fj+mt8IKsg"; logging-data="29569"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1+rfv6uhiyasHiRxNJnrtFBtSkijdbHukw=" User-Agent: Mozilla/5.0 (Windows NT 5.1; rv:8.0) Gecko/20111105 Thunderbird/8.0 In-Reply-To: <4ecd4241$0$28492$a8266bb1@newsreader.readnews.com> Cancel-Lock: sha1:jFHN3VoLMNupuFBpbPu3BIh/v/s= Xref: x330-a1.tempe.blueboxinc.net comp.lang.php:3899 Denis McMahon, 2011-11-23 19:58: > On Wed, 23 Nov 2011 10:17:45 +0100, Arno Welzel wrote: > >>>> Hint: It is also possible to implement a session handling on your own. > >>> Yup, not easy to do, though. > >> Recording a timestamp and checking if the time of the last request by >> the user (and not only the "check if session is still valid" request) is >> not older than x minutes is "not easy"? > > and the session variables? They get lost, as soon as the PHP session times out of course - but by doing periodically request using JavaScript this will not happen, so one has to implement additional logic to maintain your application specific session timeout and to distinguish between the periodically session checks via JavaScript and "real" requests caused by user interaction. In case JavaScript is not available, the session will just time out, any session variable will be lost and usually the redirection to a "session timed out" page will be done using the referrer which indicates the previous page was one which is only accessible for logged in users. If there is even no referrer you can not distinguish between a session timeout or a new session and you have to redirect to a general login page, maybe with an additional explanation like "maybe your session timed out because we did not receive any request for more than 5 minutes" or similar. -- Arno Welzel http://arnowelzel.de http://de-rec-fahrrad.de